CVE-2020-4362: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
Other sources
IBM WebSphere Application Server traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4362?
CVE-2020-4362 is classified as a privilege escalation vulnerability, which can allow unauthorized access to administrative functions.
How do I fix CVE-2020-4362?
To fix CVE-2020-4362, upgrade to the latest fixed version of IBM WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2020-4362?
CVE-2020-4362 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 up to specific patch levels.
What is the impact of CVE-2020-4362 on IBM WebSphere Application Server?
The impact of CVE-2020-4362 allows attackers to escalate privileges through token-based authentication on the SOAP connector.
Is there a workaround for CVE-2020-4362?
There is no known workaround for CVE-2020-4362; updating to a patched version is recommended.